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Information Technology Department — AADHAAR Enabled Common Residents 
Database - Creation of State Resident Data Hub (SRDH) - Administrative 
approval - Orders - Issued . * 

Information Technology fe.Gov.f) Department 

G.O.Ms. No.21 Date dr29.11*2013 

®l0cudr(uff.ajfr ^mki$D2044 


• Read; 

From the CEO, TNeGA, Chennai, Letter No.2072/TNeGA/2013, 
dated 22.04.2013. 


ORDER : 


During the Governor’s Address 2013 and Budget Speech, 2013-14, it has 
been announced that the State will create the State Residents Data Hub 
(SRDH) as a unified data repository with biometry enabled citizens’ data derived 
from the National Population Registry to service all departments. Accordingly a 
proposal has been sent by the Chief Executive Officer, Tamil Nadu ’ e- 
Governance Agency (TNeGA) to implement the announcement. The salient 
features of the project are detailed at Annexure A’ to this G.O and briefly 
described below. 


2. AIM 

State Resident' Data Hub (SRDH) is. a unified AADHAAR enabled Data 
base of all citizens. This repository will be accessed by and be available to all 
departments which deliver services to citizens. It will help the Government in 
better targeting, effective sendee delivery, greater accountability and more 
efficient monitoring of schemes. It is also proposed to use it to put in place a 
biometric or ‘AADHAAR’ based payment sj'stem to disburse welfare benefits to 
citizens. . 
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The vSRDH aims to enable the State to: 

0 Manage complete State Level Resident Data in a digitized, centralized 
and secured manner, 

c Utilise AADKAAR number to uniquely identify citizens (the 
beneficiaries of different schemes implemented by Government). 

e Integrate AADHAAR enabled National Population Register (NPR). data 
with Departmental utility Databases on a real time basis. 

• Incorporate AADHAAR au then tication in to various applications. 

3. AADKAAR SEEDING 

Seeding is the process of linking (inserting) AADHAAR number in a 
program/scheme/department database. It is critical that department/scheme 
databases are seeded with AADHAAR numbers in order to identify individual 
beneficiaries which in turn enables readiness for AADHAAR enabled sendee 
delivery, which includes both AADHAAR Enabled Payment Sendees (AEPS) 'as 
well as AADHAAR based authentication. As a part of this activity, the individual 
departments will have to contact the vendors for seeding AADHAAR numbers 
into their databases at the rates prescribed in the SRDH implementation 
contract. 

4. SRDH ARCHITECTURE 

The software components and framework of SRDH from Unique 
Identification Authority of India (UIDAI) may be used by the State which has 
seeding utilities, authentication modules etc. However, it is required to 
customize the solution/rewrite the software elements as per the State’s 
requirement and it may lead to creation of interfaces and modules in addition 
to the components available in SRDH framework. 

5. IhCPLERCENTATfOK APPROACH 

Tamil Nadu e-Governance Agency (TNeGA) through Electronic 
Corporation of Tamil Nadu Limited (ELCOT) under the Information Technology 
Department of Government of Tamil Nadu will be the nodal agency for 
implementation and maintenance of SRDH. It is the responsibility of the 
individual departments for seeding AADHAAR from SRDH and using it in their 
applications. . 

Detailed guidelines for the implementation of the project in a phased 
manner are included as Annexure T3’ to this G.O. 
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6. SELECTION OF AGENCY 

To facilitate the setting up of SRDH by State Governments, UIDA1 has 
empanelled vendors for SRDH implementation. The State Government is 
required to invite an Expression of Interest (EOI) from the empanelled vendors 
lor SRDH implementation ( and Request for Proposal from the respondents, or 
call for proposal through an open tender. There will be a Selection Committee 
consisting of representation from Government departments as below to 
evaluate the proposal and select the vendor. 

1. Secretary to Government, Information Technology Department - Member 
II. Managing Director, ELCOT/Chief Executive Officer, TK'eGA - Convenor 
HI. State Informatics Officer, National Informatics Centre (NIC), Chennai 
Member 

IV. Secretary to Government (Expenditure), Finance Department - Member 

The Technical and financial proposals that will be invited from vendors for 
implementing SRDH will include the following components: 

a) Software Development 

b) Information Technolog)'' infrastructure establishment (Hardware, 
networking and other equipment) 

c) Data services (Seeding activities which may include Data Extraction, 
Cleansing and Transformation) (The rates would be charged on per- 
record basis) 

d) Programme management 

e) Operation and Maintenance sendees for Hardware and Software. 

7. IMPLEMENTATION PERIOD 

......, 'Initially the NPR’s d 5 mamic data will be created in the SRDH in whichever 

District the National Population Register (NPR) coverage is 70-80%, Over a 
period of 1-2 years, the resident data creation in SRDH.is expected to reach 95- 
100% level through the NPR’s Taluk level facilitation counters. 

The implementation agencj' will be required to implement the Project 
within a period of 5 years (including Operation and Maintenance) from date of 
issue of order, which may be extended for a period of two years at mutual 
consent at the mutually agreed rate. 
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8, GOVERNANCE STRUCTURE 

The Governance structure comprises State Apex Committee, Project 
Implementation Monitoring Committee and Project Management Unit. Their 
Roles and Responsibility are described below;-. 

i. . State Apex Committee is headed by Chief Secretary, Principal 
Secretaries/Secretaries of concerned Departments. 

n. The Project Implementation Monitoring Committee will be chaired by the 
Secretary to Government, Information Technology Department/ Chief 
Executive Officer, TNeGA. 

Hi. TNeGA/State e-Mission Team (SeMT) will be the Project Management Unit 
(PMU) for implementing and monitoring the SRDK. 

iv. NIC will be the technical advisor for providing 
e-Government / e-Governance Solutions adopting best practices, integrated 
sendees and global solutions in Government Sector. 

v. ELCOT will proride infrastructure support for deployment of applications in 
the State Data Centre. 

ri. Department nodal officers of the respective departments are responsible for 
verifying the correctness of the citizen data of the department and linking it 
to the corresponding AADHAAR number using appropriate 
tools/methodologies/ processes. 


9. ESTIMATE COST SUMMARY ART) SOURCE O F FUND 

For Application Development and Operation & Maintenance (O&M) 
(without Disaster Recovery) 

(a) Application Development - Rs. 10.62 

(b) Operations and Maintenance - Rs. 9.28 


Rs. 19.90 

For Disaster Recovery 

(with Operation & Maintenance) Rs. 6.03 


TOTAL Rs.25.93 Crores 


(Rupees Twenty Five Crores and Ninety Three Lakhs only) 

Software development for the SRDH will be carried out utilising the 
funds to be provided by the UIDAI, to th'e tune of Rs. 10 Crores and the 
remaining amount shall be met through funding from the State Government. 
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10. STAKEHOLDERS AND THEIR RESPONSIBILITIES 

The following departments are the stakeholders in the SRDH project: 

1. Registrar General & Census Commissioner of India 

2. Government of Tamil Nadu / Information Technology Department 

3. Tamil Nadu e-Governance Agency (TNeGA) 

4. Electronic Corporation of Tamil Nadu {ELCOT) 

5. National Informatics Centre (NIC). 

The responsibilities of the above stake holders are detailed at Annexure TT to 
this G.O. 


11. GUIDELINES AND STANDARD PROCEDURE FOR SRDH DATA 
ACCESS BY SUB-AUTHENTICATION USER AGENCY 


A set of Guidelines and Standard Procedure for SRDH Data Access by 
Sub-Authentication User Agency are detailed at Annexure TP to this G.O. This 
will serve to guide the user Departments /Government agencies who are walling 
to use the SRDH data for AADHAAR seeding and authentication of the 
beneficiaries/ citizens/ users. 

12. The Government have carefully examined the proposal of the Chief 
Executive Officer, Tamil Nadu e-Governance Agency, and have decided to 
accord approval for the following: 

a) Nomination of Tamil Nadu e-Governance Agency (TNeGA) as tire Nodal 
Agency for the project and implementation through Electronic 
Corporation of Tamil Nadu Limited (ELCOT). 

b) Use of National Population Register (NPR) Data of residents with 
„AADHAAR number as a core database by State Government for State 

Resident Data Hub (SRDH). ' 

c) Signing of Memorandum of Understanding (MoU) by State Government 
with Unique Identification Authority of India (UIDAI) for Authentication 
Services. 

d) Signing of Memorandum of Understanding (MoU) by State Government 
with Registrar' General & Census Commissioner of India (RGI), 
Government of India (GOI), for sharing the National Population Register 
(NPR) Data. 

e) Appointment of Consultant from among the empanelled consultants of 
Unique Identification Authority of India (UIDAI) by following due 
procedures for providing Transaction Advisory Services and Project 
Management Sendees to select the s 3 'stem integrator / implementor for 

. establishing State Resident Data Hub (SRDH). . • 
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f) Engaging an agency as System Integrator for establishing and 
maintaining the State Resident Data Hub (SRDH) for five 3 'ears through 
open tender process. 

g) Administrative approval for the project at an estimated cost of Rs.25.93 
Crores (Rupees twenty five crores and ninety three lakhs only) subject to 
the UJDAI grant of Rs.10 (Ten) Crores as detailed in para 9 above. 

13. The Chief Executive Officer, Tamil Nadu e-Governance Agency is 
directed to send a proposal to seek funds of Rs.10 (Ten) Crores to Unique 
Identification Authority of India (UIDAf). He is also directed to send necessary 
proposals to Government for according financial sanction for the scheme. 

14. This order issues with the concurrence of Finance (industries) 
Department wide its U.O. •• No.69379/Secretary(Expenditure)/2013,dated 
27,11.2013. 


(BY ORDER OP TEE GOVERNOR) 

T.K. RAH/LCHAKDRAW, 
SECRETARY TO GOVERNMENT 


To 

The Chief Executive Officer, 

Tamil Nadu e-Governance Agency, Chennai-35. 

The Managing Director, ELCOT, Chennai-35. 

The Principal Secretary to Government, 

Finance Department, Secretariat, Chennai-9. 

The Principal Secretary to Government, 

Planning Development and Special Initiatives Department, 
Secretariat, Chennai-9. 

The Secretaiy to Government, 

Co-operation', Food and Consumer Protection Department, 
Secretariat, Chennai-9. 

The Secretary to Government, 

Revenue Department, Secretariat, Chennai-9. 

The Secretary to Government (Expenditure), 

Finance Department, Secretariat, Chennai-9. 

All Departments of Secretariat, Chennai-9. 

All District Collectors. -. . . 

All Hea.ds of Departments. 
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■ Technology (e.Gov.I) Department • 


Annextxre A 


(Annexure to • G.O.Ms.No.21, Information Technology Department, dated 
29.11.2013) 

rif TROD UCTTOEff 


SRDH is an application framework, which would enable the State to 
create a resident database with Know Your Resident (KYR) fields which include 
AADHAAR number, name, address, gender, date of birth, etc. Apart from 
storing KYR data of the citizens, the KYR + data collected, as part of census 
2011 activity will also be available in SRDH. The SRDH database could be 
used by the Government Departments /Agencies/ undertakings for seeding of 
AADHAAR numbers, cleansing, de-duplication and organizing data in their 
databases efficiently. 

The deplo 3 'ment of the SRDH application framework in the State Data 
Centre would create an authentication infrastructure using State AADHAAR 
data. 

SCOPE 

The SRDH scope includes: 

6 Creation of SRDH from the dynamic NPR data with real time connectivity. 

* Integrating Below Poverty Line (BPL) information from Socio-economic 
census. 

* Creation of family data for Civil Supplies Department with AADHAAR 
numbers. 

0 Enabling seeding of AADHAAR numbers in various Government scheme 
data bases like Social Security (Old Age Pension), Health Insurance, Labour 
Welfare Board and Scholarship at specific rates per data record provided by 
the selected vendors 

6 ETL (Extraction, Transformation, Loading) activities of data from various 
data sources for data cleansing and creation of SRDH 
e Development of customizable software modules for the different users, based 
on their roles and responsibilities 

c A -.tool for data seeding into Departmental ', databases of SRDH 
implementation with a provision to add supplementary seeding through 
online data input form 
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The State Informatics Officer, 

National Informatics Centre, Chennai-90. 

The Director General, 

Unique Identification Authority of India, 

Government of India, 3 rd Floor, Tower If, . 

Jeevan Bharathi Building, Connaught Circus, New Delhi-01. 

The Assistant Director General, 

UIDAI Regional Office, Khanjia Bhavan, 

No.49, 3 rd Floor, South Wing Race Course Road, Bangalore-01. 

The Registrar General and Census Commissioner. 

Ministry of Home Affairs, Government of India, 

2A, Mansingh Road, New Delhi - 110011. 

The Director of Census Operations Tamil Nadu, 

Rajaji Bhavan, E Wing, Illrd Floor, Besant Nagar, Chennai-90. 

The Secretary, 

Ministry of Communications and Information Technology, 

Government of India, Electronics Niketan, 6, 

CGO Complex, Lodhi Road, New Delhi, 110003. 

The Accountant General (R&SA Audit), Chennai-18. 

The Accountant General (A&E), Chennai-18. 

The Pay and Accounts Officer, Secretariat, Chennai-9. 

The Resident Audit Officer, Secretariat, Chennai-9. 

The Information Technology (Bills) Department, Chennai-9 (2 copies) 

Copy to:- 

The HonT)le Chief Minister’s Office, Chennai-9. 

The Secretary to Governor, Chennai-32. 

The Senior Private Secretary to Chief Secretary to Government, 

Secretariat, Chennai-9. 

The Personal Assistant to HonTfie Minister for Finance 
and Public Works Department, Secretariat, Chennai-9. 

The Personal Assistant to Hon'ble Minister for Food, Chennai-9. 

The Personal Assistant to HonTfie Minister for Revenue, Chennai-9. 

The Principal Private Secretary to the Secretary to Government, 

Information Technology Department, Secretariat, Chennai-9. 

SF/SC. 

//Forwarded / By Order// 

Section Officer?®^ 

■ 







Information 'Technology fe.Gov>!} Department 


Annexure-B 

(Annexure to G.O.Ms.No.21, Information Technology Department, dated 
29.11.2013) . 

IMPLBMENTATIQ N OF SRDH 


It is proposed to implement the project in a phased manner as follows; 


Pilot: 

SRDH will be created for the entire state with NPR database. In Pudukottai 
District, the AADHAAR enablement of OAP and PDS sendees will be taken up. 
The AADHAAR seeding into PDS database may not be required as .the NPR data 
can be used to create the family card database. 

Rollout 

After successful implementation in Pudukkottai, it will be rolled out 
throughout the State in a specified time frame depending on the coverage of 
biometry data capturing under NPR. 

The remaining sendees as identified by the following Departments shall be 
rolled out by individual Departments. 

I. Department of Rural Development - MNREGA, IAY/CM’s Green House 
Scheme. 

II. Department of Health and Family Welfare- Comprehensive Public Health 
v Insurance Scheme. 

III. Department of Labour and Employment and other Departments' - 
Schemes for unorganized Labour Welfare Boards. 

IV. Departments of Adi-Dravidar and Tribal Welfare- Scholarship Scheme. • 

V. Departments of BC, MBC and Minorities Welfare - Scholarship Scheme. 

VI. Department of Social Welfare - Welfare schemes like maternity benefit, 

Marriage Assistance. 

VII. Departments of Land Administration- Integrating the function of land 
administration. 

VIII. Departments of property Registration-Integrating the functions of 
registration. 

IX. School Education Department -’Common Database/Smart Card/Laptop 
schemes. • 






Application Programming Interface(API)/Web Services or generic connectors 
to interface with the Department applications 

Managing State Resident Data in a digitized, centralized and secured 
manner in SRDH 

Using the common e-Governance infrastructure like SDC, State Portal and 

TNSWAN to deliver .the AADHAAR enabled services to citizen 

Database and application should be capable of handling huge user base and 

transactions 

SRDH should be capable of handling at least 10% of total, authentication 
requirements in a concurrent manner from active users 
The demographic authentication shall be done through SRDH and biometric 
authentication from UIDAI 

SRDH shall be secure and sale in terms of accessibility and data storage 
and retrieval 

The entire sj'Stem shall adhere to the software development and 
implementation guidelines prescribed by Government of India and 
Government of Tamil Nadu 

Alternate disaster recovery options to be made available during 
implementation of SRDH without any data loss, till DRC (Disaster Recovery 
Centre) is established in the State. 

SRDH will be a single source of authentication of data for tire State which 
shall be accessible to individual Departments arid .their application for 
verification and validation of citizen/ beneficiaiy 

Development of common modules like AADHAAR seeding, authentication 
and integration etc., for Departments to authenticate the beneficiaries of 
different schemes. 


T.K.RAMACHANDRAN, 
SECRETARY TO GOVERNMENT 


Section OfficeT/^®-^ 
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Information Technology (e.G-ov.I) Beparfcnient 


Annexure-C 


(Annexure to G.O.Ms.No.21, Information Technology Department, dated 
29.11.2013) • 


STAKEHOLDERS AND THEIR RESPONSIBILITIES 
Registrar General Ss Census Commissioner of India 

6 Provide NPR data to State for SRDH creation 

«■ Establishing permanent mechanism to interface between NPR'database 
and SRDH 

* Signing of MoU between RGJ and Government of Tamil Nadu for data 
sharing 

c Establishing Permanent Facilitation counters at Taluks to ensure 100% 
data collection, updation, mutation and new enrollments. 

t Ensure NPR data is the sole source of core data for SRDH database. 

Government of Tamil Nadu 

° Signing of MoU between RGI and Government of Tamil Nadu for data 
, sharing 

e Signing of MoU between UIDAI and Government of Tamil Nadu for data 
sharing data biometric authentication 

e Establishing permanent mechanism to interface from NPR database to 
SRDH 

© Provide financial support to the nodal agency/Department for SRDH 
implementation 

© s Issue G.O for SRDH implementation and procedures and guidelines 


Information Technology Department 

© Overall responsibility for SRDH implementation 
© Facilitate the State Government in SRDH Implementation 
© Support the Nodal Agencj' (TNeGA) in policy level decisions and 
interfacing other Departments 

Tamil Nadu e-Gcvemance Agency (TNeGA) 

© Nodal Agenc}' for SRDH Implementation 

© Single Point of Contact to all other stakeholders with respect to SRDH 
implementation in Tamil Nadu. 












Based on the requirement, individual Departments shall work-out a plan for 
funding from the State Government/Government of India for implementing the 
AADIIAAR enabled sendee delivery as per the SRDH framework. Other 
Departments with citizens/beneficiary data bases can also use the SRDH data 
base. 


T.K.RAMACHANDRAN, 
SECRETARY TO GOVERNMENT 




Section Officer 2 ^ 
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Information Technology (e.Gov.E) De p art merit 


Anne?mre-D 

(Armexure to G.O.Ms.No.21, Information Technology Department, dated 
29.11.2013) 

Guidelines and Standard Procedures for SRDH Data Access by Sub- 
. Authentication User Agency (Sub-AUA) 

Introduction 

State Resident Data Hub (SRDH) is an application framework, which would 
enable the State to create a resident database with Know Your Resident (KYR) 
fields which include AADI-IAAR number, name, address, gender, date of birth, 
etc. Apart from storing KYR data of the citizens, the KYR+ data collected as 
part of census 2011 activity will also be available in SRDH. The SRDH 
database could be used by the Government 

Departments/Agencies/undertakings for seeding of AADHAAR numbers, 
cleansing, de-duplication and organizing data in their databases efficiently. 

The SRDH aims to enable the State to: 

« Manage complete State Level Resident Data in a digitized, centralized 
and secure manner. 

c Utilise AADHAAR number to uniquely identify the beneficiaries for 
different schemes implemented by Government. 

& Integrate AADHAAR enabled NPR data with Department utility 
Databases on real time. 

. & Incorporate AADHAAR authentication into various application. 

Purpose of the document 

This document will serve to guide the user Departments/Government, agencies 
who are willing to use the SRDH data for AADHAAR seeding and authentication 
of the beneficiaries/citizens/users. 

Data Access to the SRDH will be provided to specific Sub-AUAs through a 
secure authentication infrastructure and appropriate encryption methods only. 

Definitions 

AUA: . The Authentication User Agenc 3 ' is appointed by the State 
Government to implement and manage the State Resident Data 
Hub (SRDH). Presently, the AUA for SRDH in Tamil Nadu is 



e 'Programme management 

c Co-ordinate with all the agencies to understand the requirements of 
SRDH. 

g Consultancy support in developing application software for Government 
Departments. 

e Establish a Project Management Unit (PMU) to manage the entire 
program. 

® Study the data formats of NPR, AADHAAR and SRDH mid help the 
individual department for mapping .their primary data with AADHAAR. 

6 Consultancy Support for the Departments in AADHAAR seeding into 
their database. 

* Facilitate Departments for establishing interface with SRDH for 
verification and validation of the beneficiaries. 

< Support State, RGI, and UIDAI to establish data sharing agreements. 
g Facilitate the State on selecting Software, Hardware and network service 
providers for SRDH implementation / application modules 

implementation. 

c Co-ordination with other stakeholders based on their roles and 
responsibilities. 

Electronic Corporation of Tamil Nadu (ELCOT) 

®. SRDH implementation support to TNeGA 
® SRDH Maintenance at SDC 
® Tender processing 
® Vendor management support 

National Informatics Centre (NEC) 

& Supporting State Nodal Agency technically 

® Supporting the Departments in establishing interface to SRDH with their 
.Applications/databases' - 

® Interfacing support with AADHAAR and NPR and other Government 
agencies on need basis 


‘ T. K.RAMACHANDRAN, 
SECRETARY TO GOVERNMENT 


//True Copy// 

Section Office?? 







Tamil Nadu e-Governanee Agency (TNeGA) under the Information 
Technology Department 

Bub-ADA: Sub-Authentication User Agency consists of Government bodies, 

Undertakings and Autonomous bodies, or any other Government 
agencies who register with AUA for availing -SRDH data and 
authentication services. 

Guidelines for Sub-AUAs 

1. Agency Registration 


Any Government agency interested in becoming a Sub-AUA shall apply online 
OMLjMLh^.prom ded l ater) for registration. The SRDH application will have an 
online workflow based application form for engaging Sub-AUAs. The Sub-AUA 
registration can also be done offline through a hard copy of the Sub-AUA 
Application Form as provided in the Annexure E. The right to accept, reject, 
review or call lor further information/clarification rests with the AUA arid the 
decision of the AUA will be final in this regard. 

2. SRDH Access 

The SRDH data access is provided for the following purposes only: 

6 for Biometric Authentication of a Resident, especially for beneficiary 
verification 

e for Verification / Validation of Demographic Information of Citizens 

e for downloading Demographic Information of citizens for Aadhaar seeding 
, purposes 

© s for downloading Biometric Information of citizens for any special purpose 
(for which the approval of the State Apex Committee is mandatory). 

The AUA reserves the right to add, revise, suspend in whole, or in part any of 
the access rights to Sub-AUA at any time in its sole discretion, for any reason 
whatsoever. 

SRDH data is the personal information of citizens and strict confidentiality is to 
be maintained as per the laws in force . Hence, the Sub-AUA shall ensure that 
all infrastructure such as Server, Databases, Network, etc., required for SRDH 
data access and storage shall be confined within the territory of India. 

3. Outsourcing 

In the event the Sub-AUA outsources part(s) of its operations to other entities, 
the Sub*-AUA shall be responsible to AUA,‘ for all data‘access requests by the 





outsourced agency. The Sub-AUA shall intimate the complete details of the 
outsourced agency to AUA before providing access details to such agencies 

4. Confidentiality, Data Protection, Security and Use of Information 

. Access of information from SRDH is provided solely for legitimate purpose(s) as 
mentioned in the approved application form. The Sub-AUA or any of its 
outsourced agencies shall access the SRDH for no- other purposes than the 
purpose approved by AUA. 

The vSub-AUA shall not in an 5 ' manner whether directly or indirectly use the 
SRDH access for any anti-Government or discriminatory or related to money 
laundering or in contravention of any laws applicable in India. 

The Sub-AUA (and its outsourced agencies) shall treat all information of the 
Citizens taken from SRDH as confidential. It shall not, at any time, divulge 
such data to any third party or to any person voluntarily, accidentally or by 
mistake. 

The Sub-AUA shall ensure compliance with all applicable laws and regulations 
including but not limited to regulations on data protection under the 
Information Technology Act 2000 and subsequent amendments thereon, when 

accessing information for their purposes. * 

«• 

The Sub-AUA shall not store or preserve an}' data downloaded from SRDH in 
any form other than as prescribed by AUA from time to time. The Sub-AUA 
should ensure that the data received from SRDH are stored wherever 
necessary, with strong and standard encryption algorithms. 

The Sub-AUA and its outsourced agencies are prohibited from storing the 
personal identification information of citizens (like biometric information) in 
any authentication device. Storage of such data in the database server or any 
othety storage devices should be encrypted with strong and standard 
encryption algorithms. It must also be ensured that transmission of such data 
through electronic media/network is also carried out in similar encrypted 
format. * • 

The-Sub-AUA shall ensure all measures, including security safeguards, to 
ensure that the information of citizens taken from SRDH and in their 
possession or control is secured and protected against any loss or 
unauthorised access or use or unauthorised disclosure thereof. 

AUA assumes no responsibility or liability for any action or inaction, use or 
misuse of the Confidential Information and-other data in the control of the 
Sub-AUA. Any loss, damage, liability caused or suffered by the Sub-AUA or its 
outsourced agencies due to disclosure of information of confidential nature 



shall be borne by Sub-AUA without transferring any liability or responsibility 
towards the AUA. 

5. API for Secure Access 


The Sub-AUA shall strictly conform to Security' Standards and Requirements 
prescribed by UIDAI and Registrar General of India (RGI). The download of API 
and its implementation shall be provided only to the Sub.-AUA based on the 
credentials provided. The Sub-AUA shall use the API to access the SRD1T 
services without compromising or violating requirement specified by the AUA 
with regard to network specifications, security etc., from time to time. The 
Sub-AUA shall ensure fair usage of the API avoiding any kind of malpractice or 
misuse including (not limited to) reverse engineering, hacking, corrupting, 
redeveloping or disrupting its form or functionalities. 


Any violation in this regard by any of the outsourced agencies of the Sub-AUA 
should immediately be informed to AUA. 


6. Connectivity 

No direct database level connection to SRDH will be provided to the Sub-AUAs. 
1 he Sub-AUA should access the sendees of SRDH only through secured 
network connections (SSL). Performance / Latenc}^ of SRDH data access will 
depend on the strength of connectivity and limitations imposed by the network 
and hence, the Sub-AUA shall ensure better connectivity for better 
performance. 

7. Audit of Standards (QC) 


The Sub-AUA shall comply with standards, directions, specifications, orders 
etc. with respect to network and other Information Technology infrastructure, 
processes, procedures, etc., issued by the Government of India, especially 
UIDAI, RGI and Department of Electronics & Information Technology (DeitY) for 
accessing SRDH data. This conformance shall be initial!}' certified by a 
registered body (STQC or Cert-In empanelled agency) and open for periodic 
. audits in future. 

The biometric derices used for SRDH biometric authentication shall conform to 
the standards prescribed by UIDAI for Aadhaar authentication, as found at: 

( http://stqc.gov.in/sites/upload ffles/stqc/files/STOC%20UIDAI%20BDCS-03 - 
0 8%20UIDAl%20Biometric%20Device%'20Specifications%20 Authentication 1 . 

Rdf 









8. Training of Personnel 


The Sub-AUA shall ensure that persons employed for providing / enabling 
SRDH data access, maintaining necessary systems, infrastructure, processes, 
etc. possess requisite qualifications for undertaking such works. The Sub- 
AUA shall also ensure that personnel are suitably and adequately trained to 
handle the devices used for SRDH purposes. 

9. Periodic Audit 


The Sub-AUA shall be responsible to AUA for all its SRDH data access related 
aspects, and m the event the Sub-AUA outsourcing pari(s) of its operations to 
other entities, the ultimate responsibility for the results of SRDH data access 
related operations entirely lies with the Sub-AUA. The Sub-AUA shall ensure 
that the entity to which it has outsourced its operations is audited periodically 
by information systems auditor certified by a recognized body (STOC or Cert-In 
empanelled agency). 


T.K.RAMACHANDRAN, 
SECRETARY TO GOVERNMENT 


//True Copy// 










Information Technology (e.Gov.I) Departmen t 
Annexure E 


(Annexure to G.O.Ms.No.21, Information Technology Department, dated 29.11.2013) 


Organization Details 

1 

Sub-AUA Organization Name 

• 

Sub-AUA Organization Short Name 

Complete Postal Address i 

. 

Organization Type 
(Select any one option) 

! » Central Government Ministry / Department 
c State Government Ministry' / Department 

0 Public Sector Undertaking 
: < Authority constituted under the Central / State Act 
* Not-for-profit Company / Special Purpose 

Organization of national importance 
e Bank & financial institution 

1 0 Telecom Sendee Provider 
! e Others tPls specify *. ) 

Industry Sector * 

(Can select multiple options) 

■v 

* Social Sector 

e Banking & Finance 

* Telecom 

° Petroleum & Natural Gas 

* Hospitality ‘ 

* Education 

* Health care 

* Agriculture 

e Labor & Employment 

‘ Others (Pis specify ) 

Contact Details 

• 1 ; ■■■ . 11 • .. • :■ 

Management Point of Contact 

--—.. 


Contact Name 


Designation 


Mobile Number 


■Email Address 


• Fax Number 







Technical Point of Contact 


Contact Name 


Mobile Number 


Email Address 


Fax Number 



Autheafieafloji Rea triremeats' 


Scope Document 
(Please attach the document) 


Usage of authentication 
(Can select multiple options) 


Existing beneficiary authentication mechanism 
(Can select multiple options) 


Target beneficiaiy population 
(Specify the population size in numbers) 

Expected authentication volume 
(Select any one option) 


Expected authentication frequency (per 
beneficiaiy) 

(Select any one option) 


* Cleaning existing beneficiaiy database 
c Adding new beneficiaries 

° Confirming beneficiary presence 
c Financial transactions 

* Access control 

c Address verification 

* Demographic data verification 

* Attendance management 
° Accountability tracking 

* Others (pis specify)_ 


D Any ID card 
" ID ( card 
> Signature 

Magnetic / Smart card 
Password / PIN 
OTP 

Others (pis specify)__ 


* Less than 1000 per day 
1 1000-10,000 per day 

1 10,000-100,000 per day 

’ Morc th an 1 00,000 per day 
■■ Daily ' ~ 

Weekly 
Fortnightly 
Mont lily 
Quarterly 
Half yearly 
Annual. . 
Sporadic-frequent 
Sporadic-infrequent 
One time only • 
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Authentication factors 
(Can select multiple options) 

*' Personal Identity 

* . Personal Address 

* OTP 

c Fingerprint 

1 his 




Demographic matching options 
(Can select multiple options) 

Full / Partial / Focal Language 




Geographies Catered to 

(Please specify states in case multiple states / 

single state selected) 

Pan State 

• « Multiple Districts 
* District level 

• 



Possible locations of Devices/Terminals 
(Can select multiple options) 

Urban / Rural / Semi Urban 




Will charge* residents for authentication service? Yes / No / May Be 


Will financial transactions be carried out based 
on authentication? r es / No 


Readiness Activities' 



‘ Based on enrolment KYR+ data 


° Demograpliic authentication 

Aadhaar seeding strategy 

; «■ Biometric authentication 

(Can select multiple options) 

• Not Applicable .. 
e Others (pis specify) * 

Fraud monitoring capabilities 

$ 

Yes / No / In Future 


Device form factor 
(Can select multiple options) 


Authentication environment 
(Can select multiple options) 


How many devices to be deployed 
(Select any one option) 


Connectivity supported 'between 'Sub- AUA & 
I devices 

(Can select multiple options) 

Connectivity supported between sub-AUA & 
ISP(Network Sendee provider)fCVw select . 
multiple options) 


• Kiosk 

c Laptop / PC 

• Mobile phone 

• Others (pis specify)_ 

• Resident owned devices 

• Kiosks 

‘ Operator assisted 

• Operator authenticated 
1 Less than 500 

• 500-5000 

• 5000-50,000 
More than 50,000 

: GSM / CDMA “ 

• PSTN 

1 Leased line 

’ Others (pis specify)_ 

VPN ‘ “ 

Leased line ' 

Others (pis specify)_ 


Agree to Sub-AO A guidelines, and procedures 
issued bv AUA? .. 


Yes / No 








Submitted By (from AUA organization) 

Approved By (from VIDAI) 

Signature: 

Signature: 

Name: 

Name: 

Designation: 

Designation: 

Organization: 

Organization: 


T.K.RAMACHANDRAN 
SECRETARY TO GOVERNMENT 


//True Copy// 



Section Officer. 






